Platform / DevSecOps Engineer - Secure AI Systems

3MMaplewood, MN
$145,676 - $178,049Onsite

About The Position

This position provides an opportunity to transition from other private, public, government or military experience to a 3M career. As a Platform / DevSecOps Engineer - Secure AI Systems, you will be the principal hands-on owner of the secure platform foundation for a new-to-the-world AI architecture. You will design, build, automate, operate, secure, and ensure recoverability of an evolving environment that spans isolated cloud networks, hybrid infrastructure, and a future fully air-gapped on-premises platform. Working in partnership with the program's senior technical team, you will establish the foundation early, shape architecture decisions, and remain directly accountable for how the platform performs in real environments. Architecting and implementing scalable runtime components for real-time inference, near-real-time reasoning, large offline simulations, cloud services, on-premises deployments, and embedded or edge environments. Own the end-to-end operation of business-critical collaboration and software-development platforms, including the compute, storage, networking, database, and runner infrastructure supporting isolated and air-gapped environments. Establish, build, and operate the secure platform foundation, with accountability for availability, performance, capacity, cost, maintenance, and day-to-day reliability. Design and enforce Zero Trust boundaries across public, quarantine, DMZ, cloud, on-premises, developer, and internal application environments using segmentation, least-privilege access, and controlled ingress and egress. Administer GitHub Enterprise Server, including repositories, permissions, ephemeral Actions runners, audit logs, upgrades, backups, and disaster-recovery configurations. Integrate identity, privileged-access, secrets, key, and certificate services using federation, SAML, OIDC, RBAC, conditional access, credential rotation, and lifecycle controls. Design, develop and operate a controlled software-supply-chain pipeline that scans, validates, traces, and securely promotes trusted source code, packages, containers, firmware, and other artifacts into protected environments. Engineer geographically redundant backup, replication, restore, and failover capabilities across cloud and on-premises environments, with recovery proven through routine testing. Automate, monitor, and continuously secure the platform using reusable Terraform modules, scripting, centralized observability, vulnerability remediation, threat modeling and hunting, security reviews, threat detection. Lead major incident-response activities, including investigation, containment, recovery, root-cause analysis, and implementation of corrective actions.

Requirements

  • Bachelor's degree or higher in computer science, computer engineering, cybersecurity, or information systems (completed and verified prior to start) OR High School Diploma/GED (completed and verified prior to start) and seven (7) years of experience building, operating, automating, securing, or recovering business-critical technology platforms and infrastructure.
  • Seven (7) years of professional experience in platform engineering, DevSecOps, site reliability engineering, cloud infrastructure, infrastructure security, or a related field.
  • Three (3) years of hands on experience designing, deploying, and operating infrastructure using Terraform across public cloud (AWS, Azure, GCP) and private cloud/virtualization technologies (e.g., OpenStack, VMWare).
  • Three (3) years of production experience administering GitHub Enterprise Server or a comparable self-hosted software-development platform, including identity, permissions, automation runners, audit logging, upgrades, backup, and recovery.
  • Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status).

Nice To Haves

  • Three (3) years of scripting and software-development capability using scripting languages like Python, Bash, and/or PowerShell, with disciplined use of source control, code review, testing, release management, and documentation.
  • Hands-on experience designing, deploying, and managing highly scalable Kubernetes environments.
  • Hands-on experience building greenfield infrastructure platforms and operating critical systems in air-gapped, disconnected, or highly isolated production environments.
  • Experience serving as the technical owner of mission-critical production enterprise platforms supporting multiple engineering teams, including responsibility for architecture decisions, operational readiness, reliability, security, and disaster recovery.
  • Experience deploying and operating physical infrastructure, including servers, storage, networking, and virtualization platforms.
  • Experience designing and implementing systems that protect sensitive intellectual property or regulated information in environments such as trade-secret-intensive research, government, defense, healthcare, critical infrastructure, classified, or export-controlled programs.
  • Experience implementing and maintaining compliance controls aligned with cybersecurity frameworks such as NIST CSF, FedRAMP, CMMC, DoD STIGs, or comparable security standards.
  • A hands-on, low-ego working style; strong security judgment; comfort operating under ambiguity; and discretion when handling highly confidential or access-controlled intellectual property.
  • Experience working with Agile Scrum methodologies.

Responsibilities

  • Own the end-to-end operation of business-critical collaboration and software-development platforms, including the compute, storage, networking, database, and runner infrastructure supporting isolated and air-gapped environments.
  • Establish, build, and operate the secure platform foundation, with accountability for availability, performance, capacity, cost, maintenance, and day-to-day reliability.
  • Design and enforce Zero Trust boundaries across public, quarantine, DMZ, cloud, on-premises, developer, and internal application environments using segmentation, least-privilege access, and controlled ingress and egress.
  • Administer GitHub Enterprise Server, including repositories, permissions, ephemeral Actions runners, audit logs, upgrades, backups, and disaster-recovery configurations.
  • Integrate identity, privileged-access, secrets, key, and certificate services using federation, SAML, OIDC, RBAC, conditional access, credential rotation, and lifecycle controls.
  • Design, develop and operate a controlled software-supply-chain pipeline that scans, validates, traces, and securely promotes trusted source code, packages, containers, firmware, and other artifacts into protected environments.
  • Engineer geographically redundant backup, replication, restore, and failover capabilities across cloud and on-premises environments, with recovery proven through routine testing.
  • Automate, monitor, and continuously secure the platform using reusable Terraform modules, scripting, centralized observability, vulnerability remediation, threat modeling and hunting, security reviews, threat detection.
  • Lead major incident-response activities, including investigation, containment, recovery, root-cause analysis, and implementation of corrective actions.
  • Ensure corporate policies, procedures and security standards are complied with while performing assigned duties.
  • Contribute to a strong Environmental Health and Safety (EHS) culture by following safety policies, identifying hazards, and engaging in continuous improvement.

Benefits

  • Medical, Dental & Vision
  • Health Savings Accounts
  • Health Care & Dependent Care Flexible Spending Accounts
  • Disability Benefits
  • Life Insurance
  • Voluntary Benefits
  • Paid Absences
  • Retirement Benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service